Account Re-activation Conditions in Password Policy - Identity Manager
search cancel

Account Re-activation Conditions in Password Policy - Identity Manager

book

Article ID: 137784

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article clarifies the behavior of user account re-activation within Identity Manager. When a user account becomes disabled due to password policy constraints, specific conditions must be met for the account to be automatically re-activated after the defined lockout period.

Environment

Identity Manager 14.5

Cause

Account re-activation behavior depends on whether the user attempts to log in during the lockout window. Any login attempt, regardless of whether the password is correct or incorrect, resets the calculation timer for account re-activation.

Resolution

To successfully re-activate a disabled account, ensure the following conditions are met:

  1. Wait Period: Do not perform any login attempts during the period defined in the password policy.
  2. Calculation Logic: If a login attempt occurs during the lockout window, the re-activation timer will reset, extending the time required before the account is enabled.

Example Scenario:

  • Assume a password policy requires a 10-minute lockout period.
  • The account is disabled.
  • Login Attempt 1: Occurs 8 minutes after the account is disabled. This resets the timer.
  • Login Attempt 2: Occurs 16 minutes after the account is disabled (8 minutes after the first failed attempt). This resets the timer again.
  • Result: The account will only be enabled 10 minutes after the final login attempt (in this case, 26 minutes after the account was initially disabled).

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.